critical CVSS 9.8

CVE-2025-34218·Docker vulnerability

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose internal Docker containers through the gw Docker instance. The gateway publishes a /meta endpoint which lists every micro‑service container together with version information. These containers are reachable directly over HTTP/HTTPS without any access‑control list (ACL), authentication or rate‑limiting. Consequently, any attacker on the LAN or the Internet can enumerate all internal services and their versions, interact with the exposed APIs of each microservice as an unauthenticated user, or issue malicious requests that may lead to information disclosure, privilege escalation within the container, or denial‑of‑service of the entire appliance. The root cause is the absence of authentication and network‑level restrictions on the API‑gateway’s proxy to internal Docker containers, effectively turning the internal service mesh into a public attack surface. This vulnerability has been identified by the vendor as: V-2024-030 — Exposed Internal Docker Instance (LAN).

Severity
critical
Software
Docker
Fixed in
22.0.1049
Published
2025-09-29

Affected versions

Until: 22.0.1049

Fixed in: 22.0.1049

How to fix this CVE

Upgrade Docker to version 22.0.1049 or later to patch the exposed internal Docker instance vulnerability. This critical issue allows unauthenticated attackers to enumerate microservices, access internal APIs, and potentially escalate privileges or cause denial-of-service. Ensure all Vasion Print Virtual Appliance and SaaS deployments are updated immediately, and implement network-level access controls to restrict direct communication with internal container endpoints.

sudo dnf update docker-ce docker-ce-cli containerd.io

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

GET /meta HTTP/1.1|POST /meta HTTP/1.1|GET /api/v[0-9]+/services HTTP/1.1|HTTP response containing internal microservice container names, versions, or 'gw' Docker instance identifiers without 401/403 response codes

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Block unauthenticated HTTP requests to the /meta and /api/* endpoints on the appliance gateway. Implement IP-based access controls to restrict gateway access to trusted networks only. Require Bearer token or API key authentication for all gateway proxy requests to internal microservices.

How to check if you are affected

  1. Check installed Docker version: docker --version or dpkg -l | grep docker-ce (Ubuntu/Debian) or rpm -q docker-ce (RHEL/CentOS)
  2. Verify the gateway endpoint exposure: curl -s http://<appliance-ip>:8080/meta | jq . (or without jq) to see if internal microservice containers are enumerated
  3. Search Docker container logs for unauthorized API requests: docker logs $(docker ps -q) | grep -E '(unauthenticated|401|403|unauthorized)' to identify exploitation attempts
  4. Confirm patch applied: docker --version should report 22.0.1049 or higher, and the /meta endpoint should require authentication or be unavailable

Indicators of compromise

  • GET /meta (unauthenticated)
  • HTTP response body containing 'container.*version' or 'microservice' JSON objects
  • Direct internal service endpoint requests (e.g., http://<gw-ip>:8080/service-name/api)
  • User-Agent scanning for reconnaissance tools accessing /meta endpoint

FAQ

What is CVE-2025-34218?

This vulnerability exposes the internal Docker container mesh in Vasion Print Virtual Appliances through an unauthenticated gateway endpoint (/meta) that lists all microservices and their versions. Attackers can directly interact with internal APIs without authentication, leading to information disclosure, privilege escalation, or appliance-wide denial-of-service.

Is CVE-2025-34218 being actively exploited?

No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been released, though researchers have published proof-of-concept details. Organizations should still treat this as critical due to its CVSS 9.8 score and ease of exploitation.

What versions of Docker are affected by CVE-2025-34218?

Vasion Print Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 are vulnerable. All earlier Docker-based deployments of Vasion Print should be upgraded immediately.

How do I check if my server is vulnerable to CVE-2025-34218?

Run: docker --version to check your Docker version (should be 22.0.1049 or higher). Then test: curl -s http://localhost:8080/meta or curl -s http://<appliance-ip>/meta to see if the gateway endpoint exposes internal microservices without authentication.

Does Defensia detect CVE-2025-34218?

Yes — Defensia's CVE advisory scanner compares installed Docker package versions against the NVD database. If Docker is installed on a monitored server, CVE-2025-34218 will appear in your dashboard with remediation steps and version-specific upgrade commands.

Related Docker CVEs

CVE-2026-57572CVSS 10Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user. The Docker API is unauthenticated by default, so a single request yields arbitrary command execution. This issue is fixed in version 0.9.0.
CVE-2026-26216CVSS 10Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.
CVE-2026-44329CVSS 10free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can hit UPI endpoints with no Authorization header at all, and the requests reach the SMF business handlers. In the running Docker lab this was directly demonstrated for read (GET /upi/v1/upNodesLinks), write (POST /upi/v1/upNodesLinks with attacker-controlled UP-node and link payload), and delete (DELETE /upi/v1/upNodesLinks/{nodeID}) operations. This vulnerability is fixed in 4.2.2.
CVE-2026-42298CVSS 10Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev. This issue has been patched via commit da44801.
CVE-2026-40281CVSS 10Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink. This is a bypass of the incomplete key-sanitization fix introduced in v8.30.1. An unauthenticated attacker can rename or move any PDF being processed to an arbitrary path in the container filesystem, overwrite arbitrary files, or create symlinks and hard links at arbitrary paths.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-34218. Free for 1 server.

Get started free